The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →To stop WordPress from saving a commenter’s IP address in new comment records, filter pre_comment_user_ip and return an empty string before the comment is inserted. This changes WordPress’s comment-author IP field only; it does not erase existing rows or control web-server, hosting, CDN, proxy, firewall, analytics, or security-plugin logs.
Use the pre-recording filter for new comments
WordPress exposes pre_comment_user_ip before it records the incoming address. The developer reference describes it this way: “With this filter, we can change the comment author’s IP before it’s recorded.” Returning an empty string leaves the comment’s comment_author_IP field blank when WordPress inserts the new row.
Install a small site-specific plugin
Create a PHP file such as wp-content/plugins/blank-comment-ip/blank-comment-ip.php with this content:
<?php
/**
* Plugin Name: Blank IPs on New Comments
* Description: Prevents WordPress from saving commenter IP addresses in new comments.
*/
function freedom251_blank_comment_ip( $comment_ip ) {
return '';
}
add_filter( 'pre_comment_user_ip', 'freedom251_blank_comment_ip' );
- Upload the folder and PHP file to
wp-content/plugins/blank-comment-ip/. - In the WordPress dashboard, open Plugins → Installed Plugins.
- Activate Blank IPs on New Comments.
A maintained code-snippet system can also register the same callback. Keep the snippet in a site-specific location rather than a theme that may later be replaced.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
Verify that WordPress saves a blank value
Use a test account or a controlled test comment after activation. Check the saved record and the moderation workflow:
- Submit a new comment.
- Open Comments in the WordPress dashboard and inspect the comment details. The comment IP field should be blank.
- Check the underlying comment record through your normal database-administration process; the WordPress comment IP column should contain an empty value for that new row.
- Approve, hold, mark as spam, and edit the test comment to confirm that the site’s workflow still behaves as expected.
- Repeat the checks after updating or replacing comment, security, caching, or anti-spam plugins.
This verification matters because plugins can read the comment IP at different points or maintain their own data.
What this change does—and does not do
| Approach | New WordPress comment rows | Existing comments | Other logs | Moderation and spam data |
|---|---|---|---|---|
pre_comment_user_ip filter |
Leaves the WordPress comment IP field blank before insertion. | Unchanged; requires separate cleanup or an erasure process. | Unaffected; server, host, CDN, proxy, firewall, analytics, and plugin logs remain separate. | May remove an address that moderation or anti-spam integrations expect, so test them. |
| Display-only filtering or anonymization | Does not prevent the database field from being populated. | Does not delete the stored value. | Unaffected. | Can change what an administrator sees without changing what integrations can access. |
| Database cleanup or supported erasure | Does not prevent future collection by itself. | Can remove or alter historic comment data when carried out correctly. | Unaffected unless those systems are cleaned separately. | Historic moderation evidence may be lost. |
Handle IP addresses already stored
The filter runs before insertion; it is not a retroactive delete. A display filter that changes the value returned to an administrator also leaves the database value intact. For older comments, use a carefully planned database cleanup or an appropriate WordPress privacy erasure workflow, with a backup and a tested recovery plan. Decide whether moderation history, legal holds, or other operational requirements make deletion appropriate before changing historic rows.
Rank #2
Audit logging outside the comments table
WordPress’s comment field is only one possible location for an IP address. Review retention and collection settings for:
- Web-server and hosting access logs
- CDN, reverse-proxy, load-balancer, and firewall logs
- Security and anti-spam plugins
- Analytics and monitoring services
- Custom theme or plugin code
Removing the value from comment_author_IP does not prove that the address is absent elsewhere. Each system needs its own configuration and retention decision.
Check moderation and anti-spam trade-offs
WordPress documents IP addresses as possible moderation or blocklist criteria. Some anti-spam tools may also use the value. A WordPress.org support discussion reports an anti-spam compatibility problem when the comment IP filter removes the address; treat that as a scenario to test with your own plugin, not as proof that every integration fails.
After activation, test legitimate comments, moderation queues, spam classification, blocklists, rate limits, and any abuse reports. If a tool requires an IP, determine whether it can operate with another signal before keeping the filter enabled.
Privacy and retention decisions
WordPress identifies IP addresses as personal data in its privacy documentation and provides privacy-policy, export, and erasure features. Whether your site may retain an address, and for how long, depends on its jurisdiction, purpose, and circumstances; the WordPress materials do not establish one universal retention rule.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteDocument which systems collect IP information, why they collect it, how long they retain it, and who can access it. Update the site’s privacy information when the collection or retention practice changes.
Rank #4
Troubleshooting
The dashboard still shows an IP address
Confirm that the test comment was created after the plugin was activated. Then check whether a plugin is displaying a separately collected value or whether you are viewing an older comment.
Spam detection gets worse
Review the anti-spam plugin’s documented inputs and run controlled tests with the filter enabled and disabled. You may need to configure an alternative signal or accept that the plugin requires the address.
Old comments still contain addresses
That is expected. The pre-recording filter does not modify historic rows. Use a separately planned cleanup or erasure process.
Recommended Free Tools
Best Value
Server logs still contain addresses
That is also expected. Configure retention and redaction in the relevant hosting, proxy, CDN, firewall, analytics, and security systems; the WordPress hook cannot control them.
The Bottom Line
Use pre_comment_user_ip to prevent WordPress from populating the comment IP field for future comments, then separately address historic rows and every other system that may log visitor addresses.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




